kaizen-agentic/engagements/pilots/eng-coulomb-railiance01-ho-001/CUSTODY.md
tegwick d691135c4a
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
ci / test (push) Successful in 52s
docs: consolidate agent execution and custody
2026-08-20 22:43:55 +02:00

52 lines
2.4 KiB
Markdown

# Custody — eng-coulomb-railiance01-ho-001
## Decision
The engagement record and vault are owned by the `coulomb` client and classified
`client_confidential`. Their present location in `kaizen-agentic` is
transitional supplier custody, not supplier ownership.
The selected receiving authority is:
```text
repository: railiance-infra
path: docs/evidence/resource-hosteurope-railiance01/engagements/
eng-coulomb-railiance01-ho-001/
```
`railiance-infra` is the canonical S1 owner for Railiance01 inventory,
hardening, access, and host-operational evidence, and already maintains the
`resource-hosteurope-railiance01` evidence interface. `reef-railiance` is not
the target: it owns grouped reef identity, topology, and bindings, not detailed
host-operation records.
## Current data classes
| Tree | Classification | Intended custody |
|------|----------------|------------------|
| `ENGAGEMENT.yaml`, request, schedule, bound definition | client operational record | receiving repo |
| `vault/`, reports, checklists, access plan | client confidential | receiving repo |
| engagement-local `.kaizen/metrics/` | client execution evidence | receiving repo |
| `commercial/` | client settlement metadata | receiving repo or financial authority |
| reusable role craft under `roles/host-operator/` | supplier craft | remains in kaizen-agentic |
The committed access plan contains operational routing and host identity, but
no credential value. Secrets, private keys, tokens, and passwords must never be
added to this tree or to a transfer package.
## Transfer gate
The supplier copy remains the source of truth until all of these are true:
1. The receiving repository accepts the path and confidentiality policy.
2. The complete engagement tree is copied with history or an attributable
import commit, and the receiver validates its manifest.
3. The receiver records the accepted commit and acceptance date in
`vault/handoff/custody-transfer.yaml`.
4. Scheduled execution and access references are changed to the receiving path.
5. Only then may this supplier copy be reduced to a non-confidential pointer or
removed in a separately reviewed, recoverable change.
Until acceptance, do not add new sensitive operational evidence here unless it
is necessary to maintain the active engagement. Do not claim that a handoff
pack created inside this repository has itself transferred custody.